摘要
在多Agent协同入侵检测系统中,不同检测Agent并行地检测网络包中不同的入侵特征,以提高系统的检测效率。使用消息、自定义通信协议等作为系统的协同通信机制,有效地避免了系统中的单点故障,并且,该机制使得各个Agent的检测结果可以有效融合。在分析了入侵的类型、特征后,使用4个检测Agent仿真了入侵检测的过程,并在检测精度、检测误差影响很小的情况下,使检测每条记录的时间大幅度减少。
In intrusion detection system based on multi-Agent, network packets were detected simultaneously by different Agents, which improved the efficiency of the system. Through using of the message mechanism, custom communication protocol mechanism, and other mechanisms, failure of single point was avoideds, and the detection results of different Agents were effectively integrated. In this research, four Agents were used to simulates intrusion detection based on multi-Agent, and the result was given which is that the time of detection was drastically reduced while accuracy and errors of detection were influenced little.
出处
《计算机科学》
CSCD
北大核心
2008年第12期51-54,共4页
Computer Science
基金
国家自然科学基金(60574082)支助
关键词
多AGENT
入侵检测
协同
Multi-Agent, Intrusion detection, Co-operation